cbcvebase.
CVE-2009-1955
published 2009-06-08

CVE-2009-1955: The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EXPLOIT
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

Affected

19 ranges
VendorProductVersion rangeFixed in
apacheapr-util< 1.3.71.3.7
apacheapr-util>= 0 < 1.3.7+dfsg-11.3.7+dfsg-1
apacheapr-util>= 0 < 1.3.7+dfsg-11.3.7+dfsg-1
apacheapr-util>= 0 < 1.3.7+dfsg-11.3.7+dfsg-1
apacheapr-util>= 0 < 1.3.7+dfsg-11.3.7+dfsg-1
apachehttp_server>= 2.2.0 < 2.2.122.2.12
applemac_os_x< 10.6.210.6.2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapr-util< apr-util 1.3.7+dfsg-1 (bookworm)apr-util 1.3.7+dfsg-1 (bookworm)
debianapr-util
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
redhatenterprise_linux
suselinux_enterprise_server

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM